Description
The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.
Remediation
References
Related Vulnerabilities
OpenSSL Numeric Errors Vulnerability (CVE-2007-5135)
MongoDb Improper Input Validation Vulnerability (CVE-2014-3971)
Oracle JRE CVE-2013-2429 Vulnerability (CVE-2013-2429)
WordPress Plugin User Avatar Unspecified Vulnerability (1.4.6)
WordPress Plugin Pods-Custom Content Types and Fields SQL Injection (2.5.1.1)